02.10.2026, 23:18 UTC · 19 Befehle · über ssh · Estland · 2× wiederholt
user='root' pass='Vk$@+V#e-oSBgIG' root@srv01:~$ uname -a Linux web02 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64 GNU/Linux root@srv01:~$ cut -d' ' -f1 /proc/uptime 101 root@srv01:~$ sudo -l sudo: effective uid is not 0, is sudo installed setuid root? root@srv01:~$ sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "$d" 2>/dev/null && pwd && break; done' / root@srv01:~$ cat /proc/cpuinfo | grep processor | wc -l 8 root@srv01:~$ cd "/" && if [ ! -f "w.sh" ]; then cat > "w.sh" && chmod +x w.sh; fi bash: w.sh: No such file or directory root@srv01:~$ grep -E "CentOS|Red Hat|AlmaLinux|Rocky" /etc/os-release 2>/dev/null || true root@web02:~# grep -E "CentOS|Red Hat|AlmaLinux|Rocky" /etc/os-release 2>/dev/null || true root@srv01:~$ PATH=$PATH:/usr/bin:/usr/local/bin root@srv01:~$ CRON="$(crontab -l 2>/dev/null || true)" root@srv01:~$ if ! echo "$CRON" | grep -F '//w.sh "astats" "netai" "kstats" "ssh 1 az"' >/dev/null 2>&1; then bash: syntax error near unexpected token `then' root@srv01:~$ (echo "$CRON"; echo '@reboot //w.sh "astats" "netai" "kstats" "ssh 1 az"'; echo '0 * * * * cd "/" && ./w.sh "astats" "netai" "kstats" "ssh 1 az"') | crontab - bash: syntax error near unexpected token `(' root@srv01:~$ fi bash: fi: command not found root@srv01:~$ ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10 PID %CPU COMM 1234 2.3 python3 1098 1.1 nginx 876 0.5 sshd 654 0.3 systemd-journal 432 0.2 systemd-udevd 321 0.1 cron 210 0.1 rsyslogd 198 0.0 systemd-logind 176 0.0 dbus-daemon 154 0.0 systemd root@srv01:~$ ps aux | grep netai | grep -v grep | wc -l 0 root@srv01:~$ cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root || cd / && cat > netai root@srv01:~$ CRON="$(crontab -l 2>/dev/null || true)" root@srv01:~$ echo "$CRON" | grep -F '//w.sh "astats" "netai" "kstats" "ssh 2 az"' >/dev/null 2>&1 || \ bash: syntax error near unexpected token `|' root@srv01:~$ printf '%s\n%s\n' "@reboot //w.sh "astats" "netai" "kstats" "ssh 2 az"" "0 * * * * cd "/" && ./w.sh "astats" "netai" "kstats" "ssh 2 az"" | (cat -; echo "$CRON") | crontab - bash: syntax error near unexpected token `(' root@srv01:~$ cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root || cd / && cat > netai bash: netai: No such file or directory
Der Angreifer meldete sich per SSH mit einem erratenen Root-Passwort an. Er führte eine Reihe von Systemabfragen durch, um die Umgebung zu identifizieren und Schreibrechte zu prüfen. Anschließend versuchte er, ein Skript namens w.sh sowie eine Datei namens netai in verschiedenen temporären Verzeichnissen zu erstellen und Cron-Jobs für deren Ausführung zu installieren.
Die Befehle uname und cat /proc/cpuinfo dienten der Erkennung von Kernel-Version und CPU-Kernen. Die Schleife mit cd prüfte, in welchem Verzeichnis Schreibrechte bestehen, um dort Dateien abzulegen. Der Versuch, w.sh zu erstellen, scheiterte, da die Shell-Syntax für die bedingte Ausführung fehlerhaft war. Die crontab-Befehle sollten die Skripte als wiederkehrende Aufgaben registrieren, was ebenfalls an Syntaxfehlern scheiterte. Die ps-Befehle dienten der Überwachung der Systemlast und der Suche nach bereits laufenden Prozessen.
Das Ziel war vermutlich die Installation einer Persistenz-Komponente für ein Botnetz oder einen Kryptominer. Die Namen der Dateien und die Cron-Argumente deuten auf eine Automatisierung hin, die nach einem Neustart oder stündlich ausgeführt werden soll. Da die Shell-Befehle aufgrund von Syntaxfehlern scheiterten, blieb die Infektion auf dem Honeypot aus.
Dieses Muster ist typisch für automatisierte Skripte, die oft von Botnetzen wie Mirai oder ähnlichen Varianten genutzt werden. Die Verwendung von Standard-Verzeichnissen wie /dev/shm und /tmp ist ein häufiger Indikator für Malware-Installationen.